Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm analyst and advisor at KuppingerCole Analysts. And so are my guests. I really would like to welcome Kai Boschert and Patrick Teichmann. Both are advisors at KuppingerCole Analysts. Hi Kai and hi Patrick. Starting with Kai.
Hi, Matthias. Thank you for having me.
Hi, Matthias. And great to be back. Great to have you back. So for Kai, he's just been recently my guest, but you, Patrick, as well. And together you are working as advisors on topics with our end-user customer organizations. And this is actually where a webinar was initiated. So there has been a webinar with topics that have been discussed in various customer engagements. And so this is really straight from the real life into our advisory business. We want to talk about a topic where you, Kai, recently held a webinar about. We want to talk about IT governance.
Before we dig deeper into it, you are advisors. So I think it's a result from our advisory work, but can you please give a short definition of what you consider IT governance to be and where it plays out its strengths?
I mean, now you started with a short definition with such a complex topic, which is quite a challenging thing, but I try to keep it simple. IT governance usually can be seen as a bridge between the strategy and operations where we really try to craft the strategy and form it into operational guidelines to have a proper structure for the operations to follow strategy, but also following compliance and legal requirements from outside the company. Right.
So it's on the one hand, knowing how things should be done and then translating that into real operational guidelines, processes and policies that are capable of being implemented in real life. Is this what you would agree to, Patrick? Yes. As you know, Matthias, I like metaphors a lot and I would say the governance is kind of your compass and how you achieve your compliance.
So it gives you a view on how the organization should achieve compliance to, for example, the strategy, but also to legal requirements and equips it with the necessary tools, templates, options to actually achieve it and be compliant with whatever is demanded from the inside or the outside. Right. And so we've already used some terms which the layman and also the not so layman usually confuse with each other. So we are using strategy, governance, compliance and they are all connected, but obviously not the same, but they have overlaps.
How do you distinguish strategy, governance and compliance in practical terms for an IT organization? How can you convey the message, which is what and why do I need to do what in that context? Maybe again, starting with you, Kai? Yes. Since Patrick already provided this wonderful term of options for the governance, I really want to grab this term again for the governance part where you really receive options to follow the strategy. So now we are back at the strategy. What is the strategy? It's a future point. It's a future vision of where you want to be and what you want to achieve.
So it's a term or a static point in the future, which you can achieve with options to go there and really be there. So a strategy is very future looking while the governance is really moving forward, looking left and right and in front of you to go to the strategy, to go to this future state while the compliance really looks backwards on the whole thing, where you get your legal requirements, your requirements from risk, from the company itself and looks backwards on what did you do in the end. It's more a controlling instrument and not that providing a guideline for your company.
It's just a controlling or it's a controlling cheat shift. Right. So strategy is where I want to go. Governance helps me getting there and compliance helps me understand how I got there where I am right now. That would be the short version. If we translate that into real operational tasks, how can I think of an example to illustrate that, Patrick, is there, what would be a strategy? What would be the governance to get there?
Yeah, for example, I usually take the topics you have on the top level in the organization, for example, from your ISMS information security management system, which gives you kind of the requirements, what you need to achieve and determines the goals. They should be, of course, inspired by the legal requirements that affect your organization. But the governance really gives you or guides the organization how to achieve these defined requirements, goals of the organization and equips the operational organization with the necessary tools and the necessary options.
So it helps to actually steer the organization by achieving this. So, for example, like when it is talking about the identity and access management discipline, then you have multiple options to achieve the goals that are defined, for example, in the ISMS. And then the IT governance gives you the options, what is the correct way to do it for your application, for example, to which systems to connect what particular requirements you have to follow or you have to implement in terms of, for example, technology or processes. Right.
Anything to add from your side, Kai, or does this also reflect your view on this topic? Absolutely. But maybe to add, since you introduced the compliance, that you look on your processes, how you came to your goal. It's not only that you check how you got there, but also you verify if this really is in line with your strategy and with the legal requirements. And then you have this whole circle coming back to the strategy again. Right. And the way how you describe IT governance, that clearly makes clear for me that this is not a team-based approach in terms of just the IT team.
There is a legal team which will take care of that. But it's a team effort. This is something that needs to be done across an organization. And in the webinar that you did, Kai, you've mentioned also the importance of a proper target operating model and that this really is a key enabler for actually achieving what we've been just discussing. Maybe you can elaborate a bit more on this. How do you bring people and processes together to make this work at scale? Yes.
There you already emphasized the very key point here to have a holistic structure and a complete picture of where you want to go and to involve all the necessary stakeholders. As it is a team effort and it cannot be a single department who can achieve it. And you really need to incorporate all the different departments and structures in your company. And to really consolidate them into one picture and one moving piece, you really need to incorporate all of those different departments.
And that is where the target operating model really comes into place, where you can manage all those departments and make them to pull together in the right direction. Right. Sounds good. What does this look like in real life, Patrick? Yes. This is a very interesting point. If you have such a central function, usually some decentral functions feel like they can offload some work to this particular function, to the central IT governance function.
And it is very important when implementing this particular target operating model that you highlight IT governance as a central function supports you in achieving these goals that the organization has. But still, there is a supportive effort required by the different areas in your IT. So the application owners, for example, which are highly relevant here, need to support you in achieving this by, for example, filling your central asset management with the required information and cooperating by giving the data.
So it is really important to not let them off, but keep them chained to this process and to highlight that task within this target operating model. Right. But in the end, it is also a matter of culture, right? So to understand that governance compliance and the implementation of a strategy as part thereof is really something that needs to be understood. And this is 2025 or almost 2026. This is no longer an afterthought. This governance and compliance needs to be woven into the overall way of how organizations actually do their business, right? Yeah.
I would also phrase in a way that you have to then position IT governance not only as someone or as part of the organization, which is like just another audit organization, which is like finger pointing onto issues, but it's like a business partner which helps you really to achieve the goals and is supportive in this regards. And yeah, really, I like this picture of a business partner establishing this organization as such. Right.
One term that really, really struck me in the webinar and also in the discussions that we had is based on the notion of having a first line of defense, which is operations and the second line of defense, which is actually risk and compliance. So those who monitor things while the others have to do it.
And Kai, you came up with a one and a half line of defense or 1.5 line of defense. Yeah. Can you please elaborate a bit more on that? So you add another layer just in between, right?
Yes, absolutely. And that's what Patrick already started to emphasize here. You really need to have a business partner between risk and strategy and IT security and operational functions because we often see that there is not always the same language spoken. And therefore, it is hard for them to understand on the one hand side what needs to be done to achieve the strategic or security goals. And on the other hand side, how do I need to phrase our requirements that operation really can achieve all those requirements?
And that's where the one and a half line come into play is where they really can advise the first line, how to do things, how to actually achieve the goals, which is set by risk, is set by security or strategy, and then helping to report all those achieved goals to them. So it's really the part between the first and the second line helping to have a proper and smooth working operations. Right. But this is also stakeholder communication. Coming back to Patrick as the practitioner who has gone through all the pains of implementing such a thing, how important is this 1.5 line of defense?
From my perspective, very important because the thing is when you look at the strategic units in your organization, for example, the ISMS, which defines overall requirements, which need to be valid for the whole organization. There's a gap between this strategy and the actual doing on the operations level. And a lot of operational units often suffer that they do not know if their implementation is compliant and enough to fulfill the requirements and need some more guidance. And this is where the 1.5 line of defense really comes into play and ensures that also targeted measures are applied.
What does this mean? So, for example, if you have highly or applications that need to be highly secured and not so critical applications, for example, as the container plan or usual example, then you need someone who is like advising you can act as a sparring partner and help to make things work and to orchestrate it. Right. Make things work. How do you make things work? I think providing the right tooling, the right help in terms of documentation, plus the right stakeholder communication are key. But how can you support an organization actually in achieving their goals?
What are typical artifacts that you can provide to an organization to make it easier? So the easiest way to help an organization is usually to reduce the effort spent in complying to risk, to comply to security and be compliant in the end. So therefore, as you already state, providing templates for the organization and have a proper centralized reporting format, have it centralized. So there is one central point where everybody can find the necessary reports.
So there and the second line really has one point to contact as well as the operations where they have one central place where all the formats and templates are, where they can report into, don't need to spend time to create own report templates, which nobody understands because they always look different. So you really want to reduce redundancy and have proper communication channel in there. I would also add there. So the templates and when this all comes to play is a really good measure and method. We are now tending to recommend you to establish standard patterns.
We are, as computer scientists are going or are well known for patterns when developing solutions, but this can also be applied here. Utilize standard patterns. When is what requirement valid for which kind of application? What particular tools are necessary to stick to and to apply to and make it easy for the organization to close this gap between the strategy and the operations. And this pattern really helped there, but not only telling the rules, but also what helps you actually to fulfill these rules and to automatically know what is valid for you. Right.
I'm a big fan in almost every area to start small and then scale smart. So this really to begin at the right point. So maybe you will begin with a very small team of first line, second line and the 1.5 line in between. When it comes to growing in this area, because governance compliance is a key challenge for every business. Is there kind of recommendations that you can give when it comes to the role separation between the governance team and their design and the lead people in there? And the execution, the operations team, on the other hand, how should they communicate?
And is there a clear segregation of duties in that area? Patrick, maybe you first. Yeah. So with compliance, governance and these topics, it's always the question, is there an MVP? The thing is, as soon as you are shining a light on the issues you have in your organization, you need to close everything. So it's all about mitigation at the end. But I think the very first step is always to get a complete picture of the landscape. So where are we before rushing to solutions? Understand where are we?
And that can be with starting with a registry of all the applications, for example, and what four measures are already applied. Understand what are the requirements, what are your applications and how they are currently applied and to get an understanding. And of course, it can start with an Excel sheet.
Yeah, of course, there's always the issue. It becomes outdated quite quickly. But to start the collection of information about the applications and what four measures are applied there. And then you can start focusing on the most nagging problems, I would call it.
Yeah, the top priorities and apply a phased approach. Don't try to resolve everything in one shot. I think that is a recommendation we can give.
Yeah, keep a focused, phased approach and have a plan how to actually resolve gaps you have within your organization. Right, Kai. Any additional thoughts? I think because you've gone through some heavy effort in that area for ourselves, for Kupinger Co. Yes. So this is something that you led already. So sometimes in the end, also celebrate what you achieve.
Yes, absolutely. So the name of the game is, I think, simplification. So as Patrick stated, shining the light into the whole governance department usually tends to, OK, we have a lot of topics to cover now. And top management wants to have it closed yesterday. But in the end, this is not possible. And there you really need to focus and step a little bit back and see, OK, what are the topics we actually have and simplify them. So you have proper names for your problems. And if you can write down your problem, you are 50% done already.
So if you have all your problems properly defined and stated, you really can deconstruct them into actual tasks you need to do. And for all those tasks you need to do, you can have proper role assignments and you can find your resources to target those tasks. So therefore, you really simplify the whole structure. You name your problems and then you prioritize them. And then you have a proper roadmap in the end, which is kind of simple, but yet it's challenging to achieve in the end, of course. But you have at least an MVP in the end where you want to start and which you want to achieve.
And then from there on, you have a proper baseline which you can grow from and really scale into the whole picture. Right. I think you not necessarily always have a greenfield approach. Sometimes there are pressing issues which need to be resolved immediately. So for reducing risk and achieving governance, you might even be forced to apply a risk-based approach to that to start with where the high risks are to reduce the overall risk. So there is often a natural sequence of initiatives to execute to get to where you want to first.
I think that's also some lesson to be learned because it's not just paperwork. It's also improving your compliance governance, but also your security posture in the end because it's the same kinds of measures that you apply. We're getting to the end of this episode. And I can only highly recommend that those who are watching and who are interested in more that they follow up with Kai's webinar. So if you look just on the Copenhagen website for Kai and his name and for some terms around governance and compliance and webinar, very important, then you should be quickly there.
It's an hour of presentation plus Q&A with the audience. And I think that's really a good starting point for everything else. You are currently considering providing more research.
Of course, you're doing this in advisory work, both of you and our team, because this is a growingly important topic as we can see. But if there are any questions, if there is any demand for documentation, we are happy to take your input, dear audience, just to react on what is actually needed. And we want to be not only advisors, but also enablers of governance and compliance. So please let us know what you are interested in. And if it's the guideline, maybe there will be an advisory note by Kai explaining how to get there.
Or if you need, for example, some good templates to use as a starting point for this documentation, could be Excel, as you said, or maybe recommendations towards which software solution actually to apply. We can support in there. And please reach out to us. We are really looking for your feedback on how to evolve this topic, because it's a growing one. Before we close down, final words. I start with, oh, I don't know, with Patrick.
Yeah, I would say, as my colleague Phillip, or our colleague Phillip always says, don't start the transformation before you assess. Yeah. And this applies also here. Don't rush for a solution before you had a complete picture of your situation. So really utilize this and start with an assessment where you are with your applications and the requirements applying here, and then start the transformation. Right. Then final words from Kai for today.
Yes, of course. Final words. So I want really to emphasize what you already started. Just give us a hint, which is really interesting. Since we covered a quite big topic here within, I think, not exactly 30 minutes. And the webinar is a little bit longer. And I think all of those topics can be dived into a lot more. So really highlight us, which is interesting for you. And then we can really find the right things to speak about. Right. So it's a combination of best practices on how to do things properly in general, but then translating that into the actual organization.
That is also a task that can be done by the team itself, can be done with support by third parties. Us, others don't care. But also to provide a second pair of eyes that can support an organization in achieving that. Having said that, I want to close down. Thank you very much, Kai. Thank you very much, Patrick, for showing your different perspectives on this really evolving topic. In the first place, it sounds a bit dry. But to implement that in the end is, on the one hand, an effort, on the other hand, really beneficial.
And it goes far beyond just achieving compliance for checkbook check checkmark compliance. But it's really improving organizations as a whole. So it's really something to strive for. Thanks again, Kai. Thanks again, Patrick.
Patrick, looking forward to having you soon again and maybe talk a bit more about IT governance. Thank you very much. Thank you.